Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
5.0.0
Description
A Jira Project Manager can exploit Xporter Scheduled Report by Server-Side Injection - Remote Code Execution. An attacker could create a template with malicious code and change the output file extension before creating the Scheduled Report.
Attachments
Issue Links
- is cloned by
-
XPORTER-3157 RCE vulnerability at Multi-action Workflow Post Function
- Closed